Getting Data In

What is the recommended architecture for a Windows universal forwarder to an indexer cluster?

splunkDude2015
Explorer

What's the recommended best practice to architect a Windows universal forwarder to an indexer cluster? Is it better to forward all the Windows UF data to a VIP or just have them go straight to the indexers?

0 Karma

sduff_splunk
Splunk Employee
Splunk Employee

Splunk has an auto load-balancing capability, http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Configureforwarderswithoutputs.conf

But without knowing all the details of your environment and requirements, this may be the recommended approach.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...